CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2288

As cited

Copy frozen at (site build).

threat intel

LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress

Living off the land (LoTL) attacks abuse legitimate system tools and remote management software to evade detection, making them difficult to distinguish from normal administrative activity. The article discusses methods for identifying suspicious LoTL abuse patterns versus routine IT operations.

Why it matters: Security practitioners need to develop detection strategies that differentiate between malicious use of PowerShell and RMM tools versus legitimate admin activity to catch intrusions that bypass traditional endpoint tools.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary